CVE-2009-1979 is an unspecified vulnerability in the Network Authentication component of Oracle Database versions 10.1.0.5 and 10.2.0.4. It carries a critical CVSS score of 10.0, indicating a severe risk of compromise to confidentiality, integrity, and availability, accessible remotely with low attack complexity and no authentication required. While Oracle initially provided limited details, independent research suggests it involves improper validation of the AUTH_SESSKEY parameter length, potentially leading to arbitrary code execution. Exploit code, including a Metasploit module, is publicly available, yet there is no indication of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.0.5CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:* | ||
10.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:10.2.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.